CVE-2022-28247: Adobe Acrobat Uninstaller Hard Link Leads To Remote Code Execution
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an uncontrolled search path vulnerability that could lead to local privilege escalation. Exploitation of this issue requires user interaction in that a victim must run the uninstaller with Admin privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-28247.
What is the severity of CVE-2022-28247?
The severity of CVE-2022-28247 is high with a CVSS score of 7.3.
Which software versions are affected by CVE-2022-28247?
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier), and 17.012.3022x (and earlier) are affected.
How can CVE-2022-28247 be exploited?
Exploitation of CVE-2022-28247 requires user interaction in that a victim must run a malicious file or program.
Where can I get more information about CVE-2022-28247?
You can find more information about CVE-2022-28247 on the Adobe Security Bulletin APSB22-16.